ROOTPLOIT
Server: LiteSpeed
System: Linux in-mum-web1878.main-hosting.eu 5.14.0-570.21.1.el9_6.x86_64 #1 SMP PREEMPT_DYNAMIC Wed Jun 11 07:22:35 EDT 2025 x86_64
User: u435929562 (435929562)
PHP: 7.4.33
Disabled: system, exec, shell_exec, passthru, mysql_list_dbs, ini_alter, dl, symlink, link, chgrp, leak, popen, apache_child_terminate, virtual, mb_send_mail
Upload Files
File: /home/u435929562/domains/events.peacockindia.in/public_html/process.php
<?php 
$host = 'localhost';
$user = 'u520518518_valoevent_demo';
$pass = 'Valoevent@dem0';
$db_name = "u520518518_valoevent_demo";

// ////////////////////////////////////
// $user           = "u520518518_valoevents";
// $pass           = "3nA>:7&5kS=";
// $db_name        = "u520518518_valovents";


// $host = "localhost";
// $user = "u520518518_valoevents";
// $pass = "3nA>:7&5kS=";
// $db_name = "u520518518_valovents";

$mysqli = new mysqli($host, $user, $pass, $db_name);

/* check connection */
if (mysqli_connect_errno()) {
    printf("Connect failed: %s\n", mysqli_connect_error());
    exit();
}
if(isset($_POST['action']) && isset($_POST['seat'])){
	$sql = "SELECT * from qrcode where seat_no='".$_POST['seat']."' and status=0";
	$result = $mysqli ->query($sql);
	if($result->num_rows >0){
		$sql_update = "UPDATE qrcode set status=1 where seat_no='".$_POST['seat']."'";
		$mysqli ->query($sql_update);
		$row = $result -> fetch_array();
		$row['status'] = 'success';
		echo json_encode($row);
	} else{
	    $sql = "SELECT * from qrcode where seat_no='".$_POST['seat']."' and status=2";
	    $result = $mysqli ->query($sql);
	    if($result->num_rows >0){
	        $row = $result -> fetch_array();
	        $row['status'] = 'blocked';
	    } else {
	        $sql = "SELECT * from qrcode where seat_no='".$_POST['seat']."' and status=1";
    	    $result = $mysqli ->query($sql);
    	    if($result->num_rows >0){
    	        $row = $result -> fetch_array();
    	        $row['status'] = 'duplicate';
    	    } else {
        		$row = array();
        		$row['status'] = 'failure';
    	    }
	    }
	    echo json_encode($row);
	}
	
} else{
	$row = array();
	$row['result'] = 'No Qrcode found';
	echo json_encode($row);
}

$mysqli->close();

?>